🔒 Add CSRF protection for import and import_items.

This commit is contained in:
Klaus Weidenbach
2017-03-29 23:53:03 +02:00
parent dea4879938
commit 81736a0129
4 changed files with 8 additions and 7 deletions

View File

@@ -478,6 +478,8 @@ class Import extends \Zotlabs\Web\Controller {
if(! $account_id)
return;
check_form_security_token_redirectOnErr('/import', 'channel_import');
$this->import_account($account_id);
}
@@ -508,6 +510,7 @@ class Import extends \Zotlabs\Web\Controller {
'$pleasewait' => t('This process may take several minutes to complete. Please submit the form only once and leave this page open until finished.'),
'$email' => '',
'$pass' => '',
'$form_security_token' => get_form_security_token('channel_import'),
'$submit' => t('Submit')
));